A significant security breach has been identified in the Connective digital identity platform used extensively in Belgium, affecting over two million users. This software, developed by Nitro Software Belgium, is integral to digital identity authentication across major banks and government agencies in the country. The vulnerabilities, uncovered by James Arnott, founder of Bay Area Labs, stem from the absence of proper request authentication mechanisms. This flaw allows any website or advertisement to interact directly with the Connective application on a user's device without their consent, potentially leading to unauthorized access to eID credentials and payment information.

Compounding the issue, attackers could manipulate authentication pop-ups to trick users into revealing their eID PINs. The software allowed customization of the text within these prompts, obscuring the requesting domain and making it difficult for users to discern legitimate requests from fraudulent ones. Once a PIN was entered, attackers could generate unauthorized approval tokens, which could be used to forge legally binding electronic signatures when a user's eID card was connected to a card reader.

This breach has disrupted the trust framework of Belgium's digital infrastructure, affecting services like government portals and third-party identity providers. Although these services themselves are secure, their dependence on eID signatures leaves them vulnerable to exploitation by attackers with stolen signing capabilities. Additionally, a separate remote code execution vulnerability was found, which does not require the presence of an eID card. This flaw allows a malicious website to execute arbitrary code at the user level by exploiting how the application handles local files.

The vulnerabilities were addressed by Nitro Software 146 days after the initial report, with updates made to block unauthorized requests and improve PIN handling. The final security measures were completed in late July, though no CVE identifiers were assigned. Arnott shared his findings at DEF CON, emphasizing the risks of centralized digital identity systems and the need for thorough security validation in critical infrastructure.